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Abstract 

Recently, Boyer et al. presented a novel semiquantum key distribution protocol [M. Boyer, D. 
Kenigsberg, and T. Mor, Phys. Rev. Lett. 99, 140501 (2007)], in which quantum Alice shares 
a secret key with classical Bob. Li et al. proposed two semiquantum secret sharing protocols 
[Q. Li, W. H. Chan, and D. Y. Long, Phys. Rev. A 82, 022303 (2010)] by using maximally 
entangled Greenberger-Horne-Zeilinger states. In this paper, we present a semiquantum secret 
sharing protocol by using two-particle entangled states in which quantum Alice shares a secret 
key with two classical parties, Bob and Charlie. Classical Bob and Charlie are restricted to 
performing measurement in the computational basis, preparing a particle in the computational 
basis, or reflecting the particles. None of them can acquire the secret unless they collaborate. We 
also show the protocol is secure against eavesdropping. 
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1. Introduction 

The basic idea of secret sharing in the simplest case is that the sender, Alice, splits the secret 
message into two shares and distributes them to two receivers, Bob and Charlie, respectively, 
such that only the two receivers collaborate can they reconstruct the secret message. In a more 
general setting, an (m, n) threshold scheme, the secret message is split into n shares, such that 
any m of those shares can be used to reconstruct it. Quantum secret sharing (QSS) is the gener- 
alization of classical secret sharing and can share both classical and quantum message. QSS is 
likely to play a key role in protecting secret quantum information, e.g., in secure operations of 
distributed quantum computation, sharing difficult-to-construct ancillary states and joint sharing 
of quantum money, etc. 

Many researches have been carried out in both theoretical and experimental aspects after 
the pioneering QSS scheme proposed by Hillery, Buzek and Berthiaume[l] in 1999. HBB99 
scheme is based on a three-particle Greenberger-Horne-Zeilinger (GHZ) state. Karlsson, Koashi 
and ImotoJ2[] proposed a QSS scheme using two-particle Bell states. Guo-Ping Guo and Guang- 
Can Guo[3] presented a QSS scheme where only product states are employed. Li Xiao et al.[4] 
generalized the HBB99 scheme into arbitrary multiparties and improved the efficiency of the 
QSS scheme by using two techniques from quantum key distribution. Zhan-jun Zhang et al.[5] 
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proposed an («, ri) threshold scheme of multiparty QSS of classical messages using only single 
photons. Fu-guo Deng et al.[6] improved the security of multiparty QSS against Trojan horse 
attack with two single-photon measurements and four unitary operations. Zhan-jun Zhang and 
Zhong-xiao Man put forward a multiparty QSS protocol by using swapping quantum entangle- 
ment of Bell states[7] and a multiparty QSS protocol of secure direct communication based on 
the two-step QSDC protocol!!. 

Recently, Boyer et al. presented a novel semiquantum key distribution protocol[9] (hereafter 
we call it BKM07 protocol), in which one party (Alice) is quantum and the other (Bob) is clas- 
sical, and proved that the protocol is completely robust against an eavesdropping attempt. In 
their protocol, quantum Alice prepares a random qubit in the computational (Z) basis {|0),|1)} 
or Hadamard (X) basis {|+> = ^=(|0> + |1», |->=-±=(|0> - |1»} and sends it to Bob. They call 
the computational basis classical and use the classical notion {0,1} to describe the two quan- 
tum states {|0),|1)}. Classical Bob is restricted to performing some classical operations, such as 
measuring the transmission qubits in the classical {0,1} basis, preparing a qubit in the classical 
basis and sending it, reflecting the particle directly. Boyer et al. showed a different semiquantum 
key distribution protocol lllOll based on randomization. Different from BKM07 protocol, classical 
Bob can reorder the particles besides measuring and preparing a qubit in the classical basis. In 
this protocol, Bob reorders randomly the reflected qubits in order to avoid Eve's acquiring Bob's 
operation information on each receiving qubit. Furthermore, they proved the robustness of the 
protocol in much more general scenario. Zou et al. presented five different semiquantum key 



distribution protocols! 11] m which Alice sends three quantum states, two quantum states and 
one quantum state, respectively. Li et al. proposed two semiquantum secret sharing protocols 
(SQSS)[ 12] (hereafter we call it LCL10 protocol) by using maximally entangled Greenberger- 
Home-Zeilinger states in which quantum Alice shares a secret with two classical parties, Bob 
and Charlie. In LCL10 protocol, quantum Alice prepares a batch of three-particle entangled 
state, each of which is in the state \ip) = _L(|0) LQilL-L) + n) ]—)^—) ^ an( j sends the second 
and the third particles of each entangled state to Bob and Charlie. By utilizing the method of 
randomization or measure-resend, classical Bob and Charlie can share a secret with quantum 
Alice. Neither Bob nor Charlie can reconstruct Alice's secret unless they collaborate with each 
other. 

In this paper, we present a SQSS protocol by using two-particle entangled state. We follow 
the descriptions about classical in Ref.Jgt]. Quantum Alice can prepare two-particle entangled 
states and measure the particles in the computational basis, Hadamard basis, or Bell basis. Clas- 
sical Bob and Charlie are restricted to measuring the particle in the computational basis, prepar- 
ing a qubit in the computational basis, sending or reflecting the particles. We show that Eve's 
eavesdropping would inevitably disturb the transmission quantum states and the communication 
parties can detect Eve's attack. 

2. The description of the SQSS protocol 

Suppose the sender, Alice, wants to share a secret key with two receivers, Bob and Charlie, 
so that none of them can recover the secret message on his own. The protocol is detailed as 
follows: 

(1) Alice prepares N two-particle entangled states, each of which is in the state 

m = -Ui + o> + i-i»«;, (i) 

V2 
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where|+) = -4=(|0)+|1», |-)=4=(|0)-|1)). We denote the ordered N two-particle entangled states 
by {[Pi(B),Pi(C)], [P 2 (B),P 2 (C)], • • •, [P N (B),P N (C)]}, where the subscript indicates the order of 
each state in the sequence, and B, C represent the two particles of each state. Alice takes particle 
B from each state to form an ordered partner particle sequence, [Pi (B), P2(B),- ■ •, Pn(B)], called 
B sequence. The remaining partner particles comprise C sequence, [Pi(C), PiiC),- ■ •, Pjv(C)]. 
Alice sends B sequence and C sequence to Bob and Charlie, respectively. 

(2) When each particle arrives, Bob chooses randomly either to measure it in the computa- 
tional basis and resend it in the same state he found (we refer to this action as MEAS-RESEND), 
or to reflect it to Alice directly (we refer to this action as REFLECT). Similarly, Charlie selects 
randomly either to MEAS-RESEND it or to REFLECT it directly the time each particle arrives. 

(3) Alice stores the received particles in quantum memory and informs Bob and Charlie that 
she has received the B and C sequence particles. Bob and Charlie then publish which particles 
they chose to MEAS-RESEND and which ones they chose to REFLECT. 

(4) Alice performs one of the four operations on each received particle according to Bob's 
and Charlie's choices, as illustrated in Table 1. 



Table 1: The communication parties' operations on the particles 



Case 


Bob 


Charlie 


Alice 


(i) 


MEAS-RESEND 


MEAS-RESEND 


OPERATION 1 


(ii) 


MEAS-RESEND 


REFLECT 


OPERATION2 


(hi) 


REFLECT 


MEAS-RESEND 


OPERATION3 


(iv) 


REFLECT 


REFLECT 


OPERATION4 



OPERATION 1: To measure particle B and C in Z basis. 
OPERATION2: To measure particle B in Z basis and particle C in X basis. 
OPERATION3: To measure particle C in Z basis and particle B in X basis. 
OPERATION4: To perform Hadamard transformation on particle B and then measure parti- 
cle B and C in Bell basis. 

(i) If both Bob and Charlie select to MEAS-RESEND, Alice implements OPERATION1 to 
obtain the sifted secret message. In this case, Bob and Charlie can share a secret key with Alice 
according to their measurement results, since Alice can obtain both the parties' measurement 
results by implementing OPERATION 1, as illustrated in Table 2. 



Table 2: The communication parties' measurement results and the shared secret key 



Bob's result 


Charlie's result 


Alice's results 


Secret 


10) 


10) 


100) 





10) 


ID 


101) 


1 


ID 


10) 


HO) 


1 


ID 


ID 


HI) 






(ii) If Bob chooses to MEAS-RESEND and Charlie chooses to REFLECT, Alice carries out 
OPERATION2. Since |Y) can be rewritten as 

= -U|0+> + !!-»«;, (2) 
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it changes to |0+) BC or \1-)bc a f ter B°b and Charlie's operation. Alice measures particle B in Z 
basis and particle C in X basis, and obtains |0+) BC or |1-) BC . She can check eavesdropping in 
the transmission line according to her measurement results . That is to say, she checks whether 
the state of particle B and C is |0+) BC or \1-)bc- 

(iii) Suppose Bob selects to REFLECT and Charlie chooses to MEAS-RESEND. After Bob 
and Charlie's operation, |*F> collapses to | + 0} BC or | - 1) BC . Alice implements OPERATION3 
and obtains | + 0) BC or | - 1) BC . In this case, she can check whether the state of particle B and C 
is right according to her measurement results. 

(iv) If both Bob and Charlie select to REFLECT, Alice performs OPERATION4. After she 
performing Hadamard transformation on particle B, |*P) is changed to 

|0 + > = 4=(|00> + |ll» i ,c. (3) 
V2 

Alice can then check whether the initial two-particle entangled state is destroyed. 

(5) Alice checks the error rate in cases (ii), (iii), (iv). If the error rate is higher than the 
threshold they preset, they abort the protocol. 

(6) Alice checks the error rate in cases (i). She chooses randomly a sufficiently large subset 
from the measurement results in case (i) and announces which are the chosen particles. Bob 
and Charlie then publish their measurement results. Since Alice can obtain their measurement 
results by implementing OPERAION1, she can check the error rate according to the information 
announced by them. If it is below the threshold they preset, Bob and Charlie can then obtain the 
final shared secret key which can only be reconstructed when they collaborate with each other. 

Actually, the protocol can also be realized by using some other two-particle entangled states, 
such as 

|0> = -J-(| + 1)-|-0» BC . (4) 



3. The security for the Protocol 

So far we have presented the SQSS protocol. We then discuss the security for the present 
protocol. The key of the security of the protocol is to keep an eavesdropper, Eve or one dishon- 
est party from knowing which particles are MEAS-RESEND particles and which are REFLECT 
ones. If Eve or one dishonest party cannot distinguish MEAS-RESEND and REFLECT particles 
before step (4), Alice's operation (OPERATION2 and OPERATION3) is equal to performing 
random Z basis measurement and X basis measurement on particle B and C, which can ensure 
the security of the protocol. We show that if Eve or one dishonest party can acquire nonzero in- 
formation about the secret message, the communication parties can find errors by eavesdropping 
check with nonzero probability. 

Suppose Bob is dishonest and he has managed to get Charlie's particles as well as his own. 
We call dishonest Bob, Bob*. In this attack, we suppose Bob* has quantum capabilities. He 
intercepts the particles in C sequence and measures particles B and C in Z-basis, X-basis, or Bell 
basis. He then resends C sequence to Charlie after measurements. 

3.1. Bob* measures particle B and C in Z basis 

When Bob* performs Z basis measurement on particle B and C, the state of the whole system 
collapses to |00) BC , |01) BC , |10) BC , or |11) BC , each with probability 1/4. We then analyze the error 
rate introduced by Bob* in the four cases, respectively. 
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(1) In the case of both Bob* and Charlie choosing to MEAS-RESEND, Bob* can obtain 
Charlie's results and his eavesdropping will not introduce any error at step (6). 

(2) In case (ii), Bob* selects to MEAS-RESEND and Charlie selects to REFLECT. Suppose 
\W) collapses to |00) BC after Bob*'s eavesdropping attack. According to the protocol, Alice mea- 
sures particle B in Z basis and particle C in X basis. After Alice's measurements, |00} BC changes 
to \0+) BC or |0-) BC each with probability 1/2. As |*F> = -^=(|0+) + |1-})bc, it is impossible for her 
to obtain |0-) BC and the error rate introduced by Bob* will reach 50%. Similarly, if ^ collapses 
to |01) BC , |10) BC , or |11> BC , Bob*'s eavesdropping will also introduce an error rate of 50%. 

(3) In case (iii), Bob* selects to REFLECT and Charlie selects to MEAS-RESEND. For 
example, IT*) collapses to |00) BC after Bob*'s eavesdropping attack. Alice measures particle B 
in X basis and particle C in Z basis, and obtains | + 0) BC or | - 0) BC . Since I*!*) = -^=(| + 0) + 
| - 1))bc, it is impossible for her to obtain | - 0) BC . Thus the error rate introduced by Bob* will 
reach 50% in this case. 

(4) In case (iv), both Bob and Charlie selects to REFLECT. Alice first performs Hadamard 
transformation on particle B and then measures particle B and C in Bell basis. Suppose I*!*) 
collapses to |00) fic after Bob*'s eavesdropping attack. Alice performs Hadamard transformation 
on particle B and |00) BC changes to | + 0) BC . \ + 0) BC can be rewritten as 

I + 0> BC = -U|00> + |10» flC = \(\<P + ) + |0-> + l<A + > - \r))B C , (5) 
V2 2 

where 

\r) = 4=(|00)-|11», (6) 
V2 

|.A + > = ^p(l01> + |10», (7) 
V2 

ir> = -Uioi> - no». (8) 

V2 

As none but |</> + ) is the right state, the error rate introduced by Bob* in this case is 3/4. 

As discussed above, in the four cases, the average error rate introduce by Bob* is j * (0 + \ + 
\ + |) = £ = 43.75%. 

3.2. Bob* measures particle B in X basis and particle C in Z basis 

Suppose Bob* measures particle B in X basis and particle C in Z basis, and resends particle 
C to Charlie. After Bob*'s attack, the initial state collapses to | + 0) BC or | - 0) BC , each with 
probability 1/2. 

(1) In case (i), both Bob* and Charlie measure their corresponding particle in Z basis and 
resend their particles to Alice directly. After Bob* and Charlie performing their operations, the 
state of particle B and C collapses to |00) BC , |01) BC , |10) BC , or 1 1 eacn with probability 1/4. 
Bob* can then achieve Charlie's secret message and his eavesdropping will not be detected at 
step (6), since Alice just performs Z basis measurement on each arrived particle. 

(2) In case (ii), Alice performs Z basis measurement on particle B and X basis measurement 
on particle C. For example, if \ v ¥) collapses to | + 0) BC after Bob*'s eavesdropping, Alice obtains 
|0+)ac> |0 - )bc> |1+)bc> or |1~)bc> eacn with probability 1/4, after her measurements. If there 
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is no eavesdropping, Alice can only obtain |0+) 5C or |1-) BC - Thus Bob*'s eavesdropping will 
introduce an error rate of 50%. 

(3) In case (iii), Alice measures particle B in X basis and particle C in Z basis. After Bob*'s 
eavesdropping, |*P) collapses to | + 0) BC or | - 0) BC . In this case, Bob*'s eavesdropping will not 
introduce any error. 

(4) In case (iv), Alice performs Hadamard transformation on particle B and | + 0) BC (I - 0) BC ) 
becomes |00) BC (|10) BC ). Alice then measures particle B and C in Bell basis. As |00) BC = 
^=(|0 + > + \cf>-)) BC and |10) BC = - \>P~))bc, the error rate introduced by Bob* is 3/4. 

As a result, the average error rate introduced by Bob* in the four cases is ^*(0+^+0+|) = 
^ = 31.25%. 

In the case of Bob* performing Z basis measurement on particle B and X basis measurement 
on particle C, or measuring particle B and C in X basis, he cannot obtain Charlie's secret message 
and his eavesdropping will inevitably be detected by Alice with a certain probability. 

3.3. Bob* measures particle B and C in Bell basis 

Suppose Bob* performs Bell basis measurement on particle B and C, and resends particle C 
to Charlie after measurement. Owing to Bob*'s eavesdropping, |*P) collapses to \0~) BC or \iff + ) BC , 
each with probability 1/2. 

(1) In case (i), both Bob* and Charlie selects to MEAS-RESEND. As \4r) BC = -4(100) - 

|1 1))bc and I | A + )bc = "^fd^l) + |10))bc> B°t>* can acquire Charlie's secret message according to 
his measurement result and his eavesdropping will not introduce any error. For example, if 
collapses to \(p~) BC and Bob*'s measurement result is |0), he can infer that Charlie's measurement 
result is |0). 

(2) In case (ii), Bob selects to MEAS-RESEND and Charlie selects to REFLECT. Alice 
measures particle B in Z basis and particle C in X basis. After measurements, \(j)~) BC or \4> + ) BC 
collapses to |0-) BC , |1— > sc , |0+> BC , or |1+) BC , each with probability 1/4, as \<p~) = -^=(| + -) + 

I _ +))bc and \tfr + ) = 4=(| + +) — | ))bc- For example, suppose |*P) collapses to \<p~) BC after 

Bob*'s eavesdropping and \(j)~) BC changes to |0-) BC or \l-) BC after Alice's measurements. Alice 
will found that \Q-) BC is not the right state. Thus Bob*'s eavesdropping will introduce an error 
rate of 1/2. 

(3) In case (iii), suppose |*P) collapses to \(f)~) BC after Bob*'s eavesdropping. Alice obtains 
I + 0) BC , | + 1)bc< I _ 0)bc> or I _ 1)bc after her measurements and | + l) BC , I - 0) BC are not the 
right state. In this case, the error rate introduced by Bob* is also 1/2. 

(4) In case (iv), I 1 ?) collapses to \4>~) BC or \if/ + ) BC after Bob*'s eavesdropping. Alice performs 
Hadamard transformation on particle B and the state of particle B and C becomes 

-L(i + o) - 1 - i)) BC = ^(i0 + ) - (9) 

V2 V2 

or 

-L(i + 1> + 1 - o)) BC = ^(i0 + ) + do) 

V2 V2 

Alice will found Bob*'s eavesdropping with probability 1/2. 

Thus the average error rate introduced by Bob* in this strategy reaches 5 * (0 + 5 + 5 + 5) = 
I = 37.5%. 

6 



3.4. Bob*'s entanglement attack 

Suppose Bob* intercepts particle C at step (1) and uses it and his own ancillary particle in 
the state |0) to do a CNOT operation (particle C is the controller, Bob*'s ancillary particle is 
the target). Bob* then resends particle C to Charlie. Thus the state of particle B, C and Bob*'s 
ancillary particle becomes 

PF!> = _L(| + oo> + |-ll» BCB , = I(|000> + |100> + |01 1)-|111)W, (11) 
V2 2 

where B' denotes Bob*'s ancillary particle. According to the protocol, Bob* and Charlie choose 
randomly either to MEAS-RESEND or to REFLECT. 

(1) In case (i), all of the communication parties perform Z basis measurement and the state 
collapses to |011} BCB ,, |111) BCB ,, |000} BCB ,, or |100) BCB ,, each with probability 1/4. Bob* will 
not introduce any error and he can achieve Charlie's secret message. 

(2) In case (ii), Bob* chooses to MEAS-RESEND and Charlie chooses to REFLECT. Thus 
|*Pi) collapses to \0) B \(f> + ) CB , or \l) B \(f>~) CB ,. Alice measures particle B in Z basis and particle C 
in X basis. In view of |0> B |<A + W = ^I0>a(l + +) + I - -»cb- and \l) B \<f>-) CB , = j=\l) B (\ + -> + 

| - +))cb>, the state of three particles changes to |0 + +) BC b>, |0 - -)bcb', |1 + ~)bcb>, ° r I 1 ~ +)bcb> 
after Alice's measurements. If Alice obtains |0-) BC or \\+) BC , she detects that there must exist 
eavesdropping in the transmission line. Thus the error rate introduced by Bob* is 50%. 

(3) In case (iii), Bob* selects to REFLECT and Charlie selects to MEAS-RESEND. \¥) 
then collapses to | + 00) BCB - or | - \ \) BCB ,. Alice measures particle B in X basis and particle 
C in Z basis and obtains | + 0) BC or | - 1) BC - Thus Bob* will not introduce any error and his 
eavesdropping will not be detected by Alice. 

(4) In case (iv), both Bob* and Charlie selects to REFLECT. After Alice's Hadamard trans- 
formation, P?i> becomes |Y 2 ) = ^=(|000> + \IU)) B cb>- As 

i^2> = ^[(i0 + > + i0-»io> + (ir>-i0-»u)w, d2) 

Alice performs Bell basis measurement on particle B and C, and she will detect the existence of 
eavesdropping with probability 50%. 

Thus, in this attack, the average error rate introduced by Bob* is |*(0+i+0 + |) = \ = 25%. 

At worst, suppose there is an extremely strong eavesdropper who can acquire the commu- 
nication parties' operation information by judging whether particle B and C are entangled or 
not. The communication parties can defeat this attack strategy by utilizing order rearrangement. 
It only needs to make some slight modifications to step (2)-(3) of the previous protocol. The 
modified steps are as follows: 

(2') When each particle arrives, Bob (Charlie) first selects randomly either to measure it 
in the computational basis and resend it in the same state he found (MEAS-RESEND) or to 
reflect it to Alice directly (REFLECT). Bob (Charlie) then reorders randomly the B (C) sequence 
particles and generates a rearranged particle sequence. After order rearrangement, Bob (Charlie) 
sends the rearranged particle sequence to Alice. The order of the rearranged particle sequence is 
completely secret to others but Bob (Charlie) himself. 

(3') Alice stores the received particles in quantum memory and informs Bob and Charlie that 
she has received the B and C sequence particles. Bob and Charlie then publish which particles he 
chose to MEAS-RESEND, which ones they chose to REFLECT and the secret rearranged order 
of the particle sequence. 
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4. Conclusion 

So far we have proposed a semiquantum secret sharing protocol by using two-particle en- 
tangled state and analyzed the security for the present protocol. In the protocol, quantum Alice 
can share a secret key with classical Bob and Charlie. Bob and Charlie are restricted to measur- 
ing a particle in the classical basis, preparing a particle in the classical basis and sending it, or 
reflecting a particle directly. Neither Bob nor Charlie can reconstruct Alice's secret key unless 
they collaborate. We show the protocol is secure against eavesdropping because neither Bob nor 
Charlie can distinguish which particles are MEAS-RESEND particles and which are REFLECT 
ones. Even if Bob or Charlie is dishonest, none of them can escape from the eavesdropping 
check after acquiring the secret message of the other side. Compared with LCL10 protocol, our 
protocol is simpler because it can be realized by only using two-particle entangled states instead 
of three-particle entangled states. As the users only need to perform some classical operations 
on particles, semiquantum secret sharing can be realized at a lower cost. We only analyzed the 
security for the protocol informally and there are many difficulties to be dealt with when imple- 
menting semiquantum secret sharing in the practical scenario. We would like to explore these 
problems in the future. 
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